leapcat

Warn

Audited by Socket on Apr 1, 2026

5 alerts found:

Securityx5
SecurityMEDIUM
leapcat-trading/SKILL.md

SUSPICIOUS. The skill’s trading capabilities align with its stated purpose, but it enables autonomous financial transactions and relies on a runtime-downloaded CLI whose public provenance is only partially verified from the provided evidence. No direct credential theft or deceptive exfiltration is shown, so this is not confirmed malware, but it is a high-impact skill that should require strict user approval per action.

Confidence: 83%Severity: 78%
SecurityMEDIUM
leapcat-ipo/SKILL.md

SUSPICIOUS: the stated purpose matches the capabilities, but the skill is high-risk because it enables real financial transactions through an npx-installed CLI that handles authentication and possibly trade passwords. The main concern is not clear malware, but disproportionate trust in third-party package code for high-impact account actions without explicit per-action approval controls.

Confidence: 79%Severity: 82%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's capabilities broadly match its stated brokerage purpose, but it grants an AI agent high-risk financial and identity actions (trading, withdrawals, IPO subscriptions, KYC). The pinned npm CLI reduces supply-chain drift, yet external code execution and local token storage still create meaningful risk; the main concern is autonomous real-world impact rather than clear evidence of malware.

Confidence: 82%Severity: 78%
SecurityMEDIUM
leapcat-wallet/SKILL.md

The skill is purpose-aligned for Leapcat wallet operations, but it carries meaningful risk because it allows autonomous financial actions and routes authentication/session handling through an external CLI package. With no verified ownership evidence for the npm package and no explicit user-approval safeguard for withdrawals, this is best classified as suspicious/high-risk rather than clearly malicious.

Confidence: 80%Severity: 74%
SecurityMEDIUM
leapcat-kyc/SKILL.md

SUSPICIOUS: the skill’s purpose matches KYC operations, but it asks the agent to execute a remotely fetched CLI, authenticate through it, and upload highly sensitive identity documents and PII without clear provenance or direct endpoint transparency. This is proportionate to KYC in function, yet medium-high risk in trust and data handling.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 12:58 AM
Package URL
pkg:socket/skills-sh/leapcat-ai%2Fleapcat-skills%2Fleapcat%2F@41656bff4c0e2cd447fc63fd71e4b064edd7753a
Security Audit — socket — leapcat